Security researchers just showed that Gemini CLI, Claude Code, and Codex can all leak CI secrets from a single poisoned GitHub issue.
API keys. Tokens. Credentials.
Anyone who can open an issue on your public repo can potentially turn the agent against you.
Same prompt injection problem researchers warned about months ago.
Still not fixed.